First published: Sat Jun 06 2020(Updated: )
In WSO2 API Manager 3.0.0 and earlier, WSO2 API Microgateway 2.2.0, and WSO2 IS as Key Manager 5.9.0 and earlier, Management Console allows XXE during addition or update of a Lifecycle.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WSO2 API Manager | <=3.0.0 | |
WSO2 API Microgateway | =2.2.0 | |
WSO2 Identity Server as Key Manager | <=5.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13883 is a vulnerability that allows XXE (XML External Entity) attacks in WSO2 API Manager, WSO2 API Microgateway, and WSO2 IS as Key Manager.
The severity of CVE-2020-13883 is medium, with a severity value of 6.7.
CVE-2020-13883 allows XXE attacks during the addition or update of a Lifecycle in WSO2 API Manager.
CVE-2020-13883 allows XXE attacks in WSO2 API Microgateway.
CVE-2020-13883 allows XXE attacks in WSO2 IS as Key Manager.
To fix CVE-2020-13883, update WSO2 API Manager to version 3.0.1 or later, WSO2 API Microgateway to version 2.2.1 or later, and WSO2 IS as Key Manager to version 5.9.1 or later.
You can find more information about CVE-2020-13883 in the security advisory WSO2-2020-0727 at the following link: https://docs.wso2.com/display/Security/Security+Advisory+WSO2-2020-0727